CVE-2024-31492: High severity fortinet forticlient vulnerability
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31492?
CVE-2024-31492 is classified as a high-severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-31492?
To fix CVE-2024-31492, upgrade to FortiClient version 7.2.4 or higher for 7.2.x series or version 7.0.11 or higher for 7.0.x series.
Who is impacted by CVE-2024-31492?
CVE-2024-31492 affects FortiClientMac versions 7.2.3 and below, and 7.0.10 and below.
What types of attacks can CVE-2024-31492 enable?
CVE-2024-31492 can enable local attackers to execute arbitrary commands by writing malicious configuration files.
When was CVE-2024-31492 disclosed?
CVE-2024-31492 was disclosed by Fortinet as part of their security advisories.